Active: WordPress 7.1.3

WordPress security warnings

Urgent core and campaign notes. Update first, then verify.

WordPress 7.1.3

Security fixes

  1. Stored XSS on the Comments administration page (via pending comments)
  2. DoS in WP_Http::make_absolute_url()
  3. Second-order SQL injection in WordPress WXR export
  4. Author-role users able to sticky posts (capability weakness)
  5. Unauthenticated disclosure of comments on private and unpublished posts
  6. Imgur embeds vulnerable to XSS
  7. Forgeable parameters to {status}_{type} hook (action name collision risk)

Official WordPress 7.1.3 news post

Past warnings

Keep WordPress updated

Confirm the version on every site. Then use scans and hardening if you want a clearer picture of leftover risk.

Larger screenshot

Enlarged image